Welcome, Guest
Username: Password: Remember me
1. The "search..." box above searches the Docs & Forum Posts. The "Search" tab above just searches the Forum Posts. :side:
Please use these to search for your issue *before* creating a new message topic, as your issue may have been previously solved.
2. Please put your Club # and Club Web Address in your Forum Signature (best) OR in each post to get faster support from us.
Click here to edit your signature at the bottom of the Profile Information tab.
3. Our user and admin docs are available at: support.toastmastersclubs.org/doc "There's a doc for that!" ;)
4. There is an "Opt In" Feature for newly added members. The Opt In document explains the strikethrough member information. Click Here to View the Post
5. When posting a New Topic , please include all relevant details and be specific. When did your issue 1st occur? What operating system, browser, & browser version are you using? Did you refresh your browser cache? Are your cookies enabled? Lastly, a screen shot is often helpful.
6. Please abide by the Terms of Use . We are volunteers contributing our spare time. We are happy to assist you, so long as you are respectful and courteous.
7. We are always looking for new FreeToastHost Ambassadors to join our team and support fellow Toastmasters in their use of the FreeToastHost website system. If you are familiar with the system and have some interest, send a Send Us a Private Message.
  • Page:
  • 1

TOPIC:

Ongoing Email Hack 2 years 9 months ago #84319

  • barbara1518
  • barbara1518's Avatar Topic Author
  • Offline
  • New Member
  • New Member
  • Posts: 4
  • Thank you received: 1
Hello,
I am the President of my TM club. For the fourth day in a row, I have received obvious spam email addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. <This email address is being protected from spambots. You need JavaScript enabled to view it.>
The subject lines vary slightly but are always themed as Re: The Follow Up Again
Today's From: shows: This email address is being protected from spambots. You need JavaScript enabled to view it.; on behalf of; Toastmasters Club 4207 on behalf of Jeff Knowles <This email address is being protected from spambots. You need JavaScript enabled to view it.> however if I click Reply this address is displayed: This email address is being protected from spambots. You need JavaScript enabled to view it.

Here is header:
Delivered-To: This email address is being protected from spambots. You need JavaScript enabled to view it.
Received: by 2002:a17:907:2d93:0:0:0:0 with SMTP id gt19csp418684ejc;
Fri, 9 Jul 2021 07:20:01 -0700 (PDT)
X-Google-Smtp-Source: ABdhPJw1kIa1GPs4BOZbeq+a/7xDtvuEllnNYa9fyZV6eAYuvrmDDD8AmHOI5VCqoMh+zmc2vAv2
X-Received: by 2002:ac8:7092:: with SMTP id y18mr28057257qto.36.1625840401597;
Fri, 09 Jul 2021 07:20:01 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1625840401; cv=none;
d=google.com; s=arc-20160816;
b=vFh4gtx8HuPWOW+v1cnlIzTkhJ57tYwj3nok+jpXAvNR+wFv0ZWbSQ0mVdqQeaIoPw
ZiXJgsRGPSTLJnfIv3Cl3tGn60iuYNBaQfrz6ikSv0Q0wCPSElcF49a+xOohulEZItVb
CHfgjmOY1K1CryzJypqXjn2U7ovNF/XZKMaL6LNjchCxo3FTTPYZoj93CcVVpn0eX84N
lN67TdEr3WOrbTobVCXA27nygszvE9mY93YamYewLbq4kkLQdIAUJ8W92ONA5QZcWP7y
dIf/VK4jBSmakYOgiEc4FiMgIzBYjhCAryHhRMeh2JEWdMVsBcOOnSQVb+OxX1kFHpEe
hb8g==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;
h=dkim-signature:to:reply-to:errors-to:sender:from
:content-transfer-encoding:mime-version:date:subject:message-id;
bh=myonuRpTIgEjnpbMZhJNL6nnwGZqMWa8mefTl2pLGJ8=;
b=ze5I8+s9p7+3QnMbvDLbHUp7rP2oEadBvyANUrkGuG0+OafKM/KH73Up0WwcXMjKiy
pz0oFOBeAns9ep4GMm2PG9QjKnRj7sDavXRGwqv9VUY8Dr7u7o6HDP3VYnKcraYZN5LS
ec20WTJ/GaE9XGKDnPGmdW+Y7gzIhBmAeIcBNCJyqHhSyVQ7UeNtkFFwkHcOkQaUFw4i
5e772G0s/+vWOeBpIzzod+IfKGfCi4WDXpREt/yf7Tl0Y8Js9IXIIlD8OeoL0APhQpzT
Nao8Cl1h3Wf+SFG8kZ2cx7M2FPChMU2IVxImMfstTYTx333uA36m043FfCY/Ie3t+BLF
NTMA==
ARC-Authentication-Results: i=1; mx.google.com;
dkim=pass header.i=@toastmastersclubs.org header.s=default header.b="jS/RlEqx";
spf=pass (google.com: domain of This email address is being protected from spambots. You need JavaScript enabled to view it. designates 50.19.253.65 as permitted sender) smtp.mailfrom=server@toastmastersclubs.org;
dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=toastmastersclubs.org
Return-Path: <This email address is being protected from spambots. You need JavaScript enabled to view it.>
Received: from toastmastersclubs.org (toastmastersclubs.org. [50.19.253.65])
by mx.google.com with ESMTPS id k8si5249271qvi.195.2021.07.09.07.20.01
for <This email address is being protected from spambots. You need JavaScript enabled to view it.>
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Fri, 09 Jul 2021 07:20:01 -0700 (PDT)
Received-SPF: pass (google.com: domain of This email address is being protected from spambots. You need JavaScript enabled to view it. designates 50.19.253.65 as permitted sender) client-ip=50.19.253.65;
Authentication-Results: mx.google.com;
dkim=pass header.i=@toastmastersclubs.org header.s=default header.b="jS/RlEqx";
spf=pass (google.com: domain of This email address is being protected from spambots. You need JavaScript enabled to view it. designates 50.19.253.65 as permitted sender) smtp.mailfrom=server@toastmastersclubs.org;
dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=toastmastersclubs.org
Received: from localhost.localdomain (toastmastersclubs.org [127.0.0.1])
by toastmastersclubs.org (8.14.4/8.14.4) with ESMTP id 169EK1L6010494
for <This email address is being protected from spambots. You need JavaScript enabled to view it.>; Fri, 9 Jul 2021 14:20:01 GMT
Message-Id: <This email address is being protected from spambots. You need JavaScript enabled to view it.>
Received: from leagueofrebels.com (rachelcomey.com [100.42.69.106] (may be forged))
by toastmastersclubs.org (8.14.4/8.14.4) with ESMTP id 169EJvMH010455
for <This email address is being protected from spambots. You need JavaScript enabled to view it.>; Fri, 9 Jul 2021 14:19:59 GMT
Subject: Re: the follow up again
Date: Fri, 09 Jul 2021 14:55:37 +0200
MIME-Version: 1.0
X-Mailer-Sent-By: 1
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: 8bit
X-Spam-Status: No, score=3.9 required=5.0 tests=HTML_IMAGE_RATIO_04,
HTML_MESSAGE,KHOP_HELO_FCRDNS,MIME_HTML_ONLY,RCVD_IN_MSPIKE_H2,
RCVD_IN_PSBL,SPF_HELO_NEUTRAL,SPF_NEUTRAL autolearn=no
autolearn_force=no version=3.4.3
X-Spam-Level: ***
X-Spam-Checker-Version: SpamAssassin 3.4.3 (2019-12-06) on
toastmastersclubs.org
From: "Toastmasters Club 4207 on behalf of Jeff Knowles"
<This email address is being protected from spambots. You need JavaScript enabled to view it.>
X-Loop: This email address is being protected from spambots. You need JavaScript enabled to view it.
Sender: This email address is being protected from spambots. You need JavaScript enabled to view it.
Errors-To: This email address is being protected from spambots. You need JavaScript enabled to view it.
Reply-To: This email address is being protected from spambots. You need JavaScript enabled to view it.
To: "This email address is being protected from spambots. You need JavaScript enabled to view it." <This email address is being protected from spambots. You need JavaScript enabled to view it.>
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed; d=toastmastersclubs.org;
h=content-transfer-encoding:content-type:date:from:mime-version
:reply-to:sender:subject:to; s=default; bh=myonuRpTIgEjnpbMZhJNL
6nnwGZqMWa8mefTl2pLGJ8=; b=jS/RlEqxtlqvl50y3O4CRoib971HG3Nm+DQRn
HoTiib2ZJ8j40qg0jxKbX3yduYywRBMRja1ByV9qNZO8YRA9u40vw1wpiNOpDYSX
mMKAsfgtPXxKSeH/WdPUtjaEJ1Dicrf8m1Od0LwWXRoxhMrm4PGl4/jJY7hxJUmK
38x+jk=

I clicked to record this and the other emails as Spam. I blacklisted the This email address is being protected from spambots. You need JavaScript enabled to view it. address in Email security. Please tell me how this has happened and what I can do to make future hacks stop.

Thank you.

Barbara Kasser DTM
President
Boca Raton Noon Toastmasters #4207
The topic has been locked.

Ongoing Email Hack 2 years 9 months ago #84320

  • Brian
  • Brian's Avatar
  • Offline
  • Administrator
  • Administrator
  • Posts: 11644
  • Thank you received: 3880
1) somewhere your email address president-4207 email address has been published and is now on spammer lists.

2) FTH does have some spam prevention on the officers email addresses in email security but we do not block every unknown email as that is how external non members can contact you.

3) You have performed the correct steps and added the offending emails to your club black list. You have also notified FTH support with the email headers so we can block the source IP range and hopefully stop this current spam attack.

Thank you,

Brian McDonald DTM, PDD D61
FTH Lead Technical Support
member Cataraqui Valley Toastmaster 9560
Last edit: by Brian.
The topic has been locked.

Ongoing Email Hack 2 years 9 months ago #84331

  • SteveTheTechie
  • SteveTheTechie's Avatar
  • Offline
  • FreeToastHost Developer
  • FreeToastHost Developer
  • Posts: 13529
  • Thank you received: 3831
You can also just disable the officer email address.
Regards,

Steve James, DTM
FreeToastHost System Developer
Officer Emeritus, Mindful Communicators (Club 1966, District 52) A President's Distinguished Club for each of the last 10 years.

>>> Please put your club number in your forum profile. CLICK here to edit your profile.
The topic has been locked.

Ongoing Email Hack 2 years 9 months ago #84426

  • barbara1518
  • barbara1518's Avatar Topic Author
  • Offline
  • New Member
  • New Member
  • Posts: 4
  • Thank you received: 1
Thank you for letting me know I can disable the officer email. I think that will be the best course of action because we don't use these officer email addresses and the spam problem continues. I can't find the steps necessary to disable the officer email addresses. Can you point me in the right direction, please. Thanks in advance

Barbara Kasser, DTM
President
Boca Noon Toastmasters #4207
The topic has been locked.

Ongoing Email Hack 2 years 9 months ago #84430

  • Brian
  • Brian's Avatar
  • Offline
  • Administrator
  • Administrator
  • Posts: 11644
  • Thank you received: 3880
it is in your member profile on the website.
see under Email Settings
support.toastmastersclubs.org/doc/item/member-profile

Thank you,

Brian McDonald DTM, PDD D61
FTH Lead Technical Support
member Cataraqui Valley Toastmaster 9560
The topic has been locked.
  • Page:
  • 1
Moderators: Pamrhtaylor3jliumarc33NotLiabledeedubbleyooNSBPhyllis Kirouac
Time to create page: 0.057 seconds
Powered by Kunena Forum